Assuming this: https://developers.facebook.com/docs/whatsapp/flows/guides/implementingyourflowendpoint/#request-decryption-and-encryption is the original instructions, it says:
using RSA/ECB/OAEPWithSHA-256AndMGF1Padding algorithm with SHA256 as a hash function for MGF1; being the important part in this case.
private_decrypt defaults to RSA PCKS1 padding (which should no longer be used as it is not secure)
I’m not sure erlang crypto module supports RSA/ECB/OAEPWIthSHA-256andMGF1Padding mode.
You can try with:
:public_key.decrypt_private(cipher, key, [rsa_padding: :rsa_pkcs1_oaep_padding]) but I am pretty sure that uses SHA1 instead of SHA256.
In addition public_key:decrypt_private2/3 and the equivalent in crypto module are deprecated. I have not found what they are replaced with though. It seems that the original intent was not for encrypt/decrypt but for signing and verification. The docs suggest that they have been replaced with :public_key.sign/verify which will not help you much.
Might give you additional options to try.
We used erlang for a crypto heavy application but we used a port (Ports — Erlang System Documentation v29.0.2) to do all the asymmetric crypto operations rather than the built-in and it performed very well with stable latency compared to our java and golang equivalent apps.


















